Skip to main content
Natural is a regulated financial platform. We hold sensitive data containing identity, bank account details, and payment credentials.

What we protect

All data is encrypted in transit (via TLS v1.3) and at rest (via AES-256) through AWS KMS. On top of that baseline, the most sensitive data gets one of two additional protections:
ProtectionApplies toWhat it adds
Field-level encryptionSSN, EIN, bank account numbersEach field is encrypted with externally-held keys. Plaintext is never readable from Natural’s database or systems.
TokenizationCard dataNever stored on Natural’s systems at all. A PCI Level 1 vendor holds the card data and returns an opaque token.
  • Compliance — Identity verification and the data we collect
  • Parties — Identity types that require verification